Term Labs Governance Attack: $8.5M Recovered After $951 Exploit

6 hours ago 22
Term Labs governance attack

Term Labs has recovered every fixed-rate loan position affected by the governance attack that hit its protocol in late August, closing out a recovery effort that began after roughly $8.5 million was drained from liquid vault balances. The final position was moved back into safety at 14:52 UTC on Aug. 25, according to a new incident report from the protocol, which also laid out for the first time exactly how attackers manipulated its governance system to pull funds out of Meta Vaults tied to Term Finance.

Key takeaways

  • The Term Labs governance attack on Aug. 23 drained an estimated $8.5 million from liquid balances inside Term vaults, including roughly 2,843 ETH and 1.68 million USDC.
  • Core V1 and V2 fixed-rate lending contracts were never touched, and direct borrowing, lending and liquidation functions kept running normally throughout the incident.
  • Attackers funded two operator wallets through Tornado Cash and spent about $951 acquiring governance tokens before submitting proposals that stripped away execution delays.
  • Term Labs shut down its Meta Vaults, revoked their DAO governance roles, and recovered all affected fixed-rate loan positions by Aug. 25.
  • The protocol is now working with law enforcement and cybersecurity firms to trace those responsible.

Governance Attack Drains $8.5 Million in Liquid Vault Balances

The Term Labs governance attack was contained entirely to liquid balances sitting inside Term vaults, rather than reaching the protocol’s underlying lending markets. Security firms CertiK and PeckShield had earlier pegged the losses from the Aug. 23 incident at close to $8.5 million, made up of about 2,843 ETH and 1.68 million USDC. PeckShield later reported that the stolen USDC was swapped for roughly 1.68 million DAI.

Term Labs’ updated account confirms that figure but adds crucial context: the money that vanished came exclusively from vault strategies, not from the core system that handles fixed-rate borrowing and lending.

Fixed-Rate Lending Contracts Remained Untouched

Term Labs’ V1 and V2 contracts stayed outside the attacker’s reach for the entire duration of the incident. Supply, repayment and liquidation functions in the protocol’s direct lending markets kept operating without interruption, even as the Meta Vaults built on top of those markets were being drained. That distinction matters for anyone evaluating fixed-rate lending security across DeFi: the exploit targeted a governance layer wrapped around the vaults, not the lending engine itself.

How Attackers Used Governance Proposals and Tornado Cash Funding

The attackers never needed to break Term’s smart contracts directly — they simply voted their way into control. Two operator wallets, each funded through Tornado Cash, submitted a series of governance proposals designed to strip out the safeguards meant to stop exactly this kind of move.

The first wallet received Tornado Cash funds on Aug. 17 and, about 24 minutes later, submitted an ETH proposal titled “Vote YES to VETO the curator’s proposed vault parameter changes.” Buried inside that proposal was a change that reduced the governance Delay on the affected stack to zero, eliminating a seven-day and one-hour window during which liquidity providers could have blocked the move before it executed.

A second wallet, funded via Tornado Cash on Aug. 18, deployed a singleton contract that combined a controller, a price adapter and a counterfeit repo token into a single package. Three days later, on Aug. 21, a helper contract initialized from that singleton submitted seven governance proposals, casting the only votes on each one. Two targeted ETH strategy DAOs but were never executed; the remaining five drove the USDC side of the attack, each stripping away a three-day and one-hour execution delay from its respective governance stack. Earlier analysis of the incident found the attacker spent only about $951 acquiring enough governance tokens to seize control of votes tied to vaults holding millions of dollars in deposits — a striking illustration of how cheaply DeFi governance proposals can be hijacked when execution delays are weak or absent.

Counterfeit Repo Token Drained USDC Strategies

Once the delays were gone, the attackers moved fast. At 06:25 UTC on Aug. 23, the first executed proposal recalled four active ETH strategies — Shorewoods, August Digital, Parity Prime and Parity Core — into the Meta Vault and redirected them into a newly added strategy called frWETH-EXIT, or “Fixed Recipient WETH Exit Strategy.” The moment WETH entered that strategy, it was forwarded in full to the first operator wallet, leaving the Meta Vault holding 2,841.74 shares in a strategy that contained none of the assets it was supposed to represent — a number that lines up closely with the roughly 2,843 ETH PeckShield had already traced out of Term Finance.

Twenty-two minutes later, at 06:47 UTC, the second campaign struck five USDC strategy DAOs: Parity Prime, Parity Core, Parity HY, Parity HY v2 and RockawayX Tori. Each proposal forced its DAO to “sell” a single unit of a counterfeit repo token into its strategy at a price equal to the strategy’s entire liquid USDC balance. That sale was made possible by a contract called fmTERT, which impersonated both the controller that verifies legitimate Term instruments and the price adapter that values them. The proposals also zeroed out each strategy’s reserve ratio and maxed out its concentration limit, disabling the checks that would normally have caught the fraud. The fake token’s price was calculated through a dynamic redemptionValue() function that simply returned whatever liquid USDC happened to be sitting in the strategy at that instant — letting the attacker sell one worthless token for nearly the full balance. The proceeds were then approved and swept straight into the second operator’s wallet.

Term Labs’ Response: Recovery and Ongoing Investigation

Term Labs’ first move after the attack was to cut off further damage: it shut down its Meta Vaults and revoked their DAO governance roles, permanently blocking new deposits while still allowing existing depositors to withdraw. Yearn, whose V3 infrastructure underpinned the affected contracts, said at the time that the exploit involved a governance wrapper built specifically for Term rather than a flaw in standard Yearn V3 vaults.

The trickier problem was the fixed-rate loans still held inside the compromised vaults. Those positions hadn’t been touched directly by the attack, but their proceeds were set to redeem automatically into the same vaults the attackers now controlled once the loans matured. Term Labs got ahead of that risk by upgrading the affected contracts and physically moving the fixed-rate positions out before maturity. That effort wrapped up with the recovery of the final position at 14:52 UTC on Aug. 25, closing the loop on what could have become a second wave of losses.

Term Labs said its Meta Vaults and affected strategies remain shut down, and that shutdown work on the remaining low-activity vaults is still in progress. The protocol is also working with law enforcement agencies and cybersecurity firms, and says it has shared relevant information to support the ongoing investigation into who carried out the attack.

What the Attack Means for DeFi Governance Security

Why does an $8.5 million loss confined to “liquid balances” matter beyond Term itself? Because the attack shows how a protocol can keep its core lending logic perfectly secure while still losing millions through a governance layer that was never battle-tested against a coordinated proposal campaign.

Execution delays exist specifically to give liquidity providers a window to catch and reject malicious proposals — and this episode shows what happens when that window gets eliminated by the same vote that authorizes the theft. Just days before the Term Finance vault exploit, Binance said it had intercepted a separate malicious DAO proposal that threatened roughly $1.2 million belonging to an unnamed project, contacting the team with less than 48 hours left before the proposal could execute. That project rejected the proposal in time and reported no losses. Term’s attackers, by contrast, built the removal of those delays directly into the same proposals that stole the funds, leaving no external party a chance to intervene.

A comparable pattern surfaced earlier in August against StrongBlock, where an attacker took over an abandoned governance system and drained around $72,000 in STRONG and STRNGR tokens after gaining enough voting power to seize administrative control of the project’s Governor contract. Cheap governance-token acquisition, weak or removable execution delays, and DAO structures granted broad control over vault strategies form a recurring pattern across these incidents — one that other DeFi protocols using similar governance wrappers may want to review closely.

FAQ

How much was lost in the Term Labs governance attack?

Approximately $8.5 million was drained from Term vaults, confined to liquid balances.

Were the core lending contracts of Term Labs compromised during the attack?

No, the fixed-rate lending contracts (V1 and V2) remained secure and operational throughout the incident.

How did attackers execute the governance attack on Term Labs?

They used two operator wallets funded via Tornado Cash to submit governance proposals that removed execution delays, enabling redirection of ETH and USDC.

What measures has Term Labs taken in response to the attack?

Term Labs shut down Meta Vaults, revoked DAO governance roles, disabled new deposits, recovered fixed-rate loan positions, and is collaborating with law enforcement and cybersecurity firms.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Read Entire Article